Patch your SharePoint and edge gear first
# Patch your SharePoint and edge gear first
If you're running a ten-person shop, you don't have a security operations center. You have a person—maybe you, maybe a contractor—who spends Friday afternoon praying the updates don't break the printer. You cannot patch everything. If you try, you'll spend your entire payroll on administrative overhead and still miss the one hole that actually matters.
The goal isn't a perfect audit. The goal is to not be the easiest target on the block.
This week, the noise is loud. 23andMe is dominating the cycle with over 110 stories as bankruptcy settlements and data leaks keep the headlines churning. It’s a disaster for them, but it's a distraction for you. You aren't 23andMe. You don't have millions of genetic profiles to lose. You have a few spreadsheets, some client contracts, and a payroll file.
Stop looking at the drama and look at the CISA Known Exploited Vulnerabilities (KEV) list. That is the only list that matters for a small budget. It doesn't tell you what *could* happen; it tells you what *is* happening.
Right now, Microsoft SharePoint is the primary fire. Two specific holes, CVE-2026-56164 and CVE-2026-58644, are being hit. CVE-2026-56164 alone has triggered 9 separate stories this week. If you host your own SharePoint server and it's pointed at the open web, you are effectively leaving your front door unlocked during a burglary wave.
For a global enterprise, patching a fleet of SharePoint servers is a choreographed dance involving staging environments, change management boards, and a team of twenty people. For you, it’s a few clicks and a restart. The cost of failure is the same, but the cost of the fix is vastly lower for the small firm. Do it now. The federal deadline for these is July 19. That's three days away.
Next, look at your edge. If you use SonicWall SMA1000 appliances, you've got two new problems: CVE-2026-15409 and CVE-2026-15410. These are code injection and SSRF vulnerabilities. In plain English: someone can trick your gateway into doing things it shouldn't.
The second-order effect here is what people miss. If your edge gateway is popped, the attacker isn't just "in the network." They now have a trusted vantage point to sniff every single credential your employees use to log in. They don't need to hack your users; they just need to wait for them to type their passwords.
Then there are the Fortinet FortiSandbox holes (CVE-2026-25089 and CVE-2026-39808). If you have this gear, patch it. It’s internet-facing and it’s exploited.
Now, let's talk about what can wait.
You'll see a lot of talk about the 622 flaws Microsoft patched in their latest cycle. That number is designed to make you panic and buy a managed security service. Ignore the bulk of it. Unless a CVE is on the KEV list or has a public exploit script being shared on GitHub, it's a lower priority than your lunch.
The Oracle E-Business Suite vulnerability (CVE-2026-46817) can wait until next week. Unless you're running a massive, legacy ERP system for a mid-sized manufacturing plant, you probably don't even have this installed. The Cisco IOS vulnerability (CVE-2008-4128) is from 2008. Yes, it was added to the KEV recently, but if you're still running 18-year-old Cisco firmware on your primary routers, you have a hardware problem that a patch won't fix.
Some will argue that you should patch everything regardless of exploitation status to maintain "hygiene." This is the advice of people who get paid by the hour to maintain the systems. In a ten-person shop, time is your most expensive resource. Spending four hours patching a low-risk internal vulnerability while your SharePoint server is wide open isn't "hygiene"; it's negligence.
The most boring controls are still the most effective. If you can't patch immediately, put the service behind a VPN or a strict IP allow-list. It's a free mitigation that shrinks your attack surface from "the whole world" to "just my office."
Enterprise firms spend millions on "visibility tools" to see where they are vulnerable. You don't need a dashboard. You need a list of what's facing the internet and a commitment to update those things first.
If you're feeling overwhelmed, remember that attackers aren't usually hunting for you specifically. They are casting a wide net. By patching the KEV list, you're simply removing yourself from the easy-catch bucket.
Check your SharePoint version and your SonicWall firmware before you leave on Friday.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV The Hacker News
- Fresh SharePoint Vulnerability Exploited Soon After Disclosure SecurityWeek
- President Trump Unveils Election Integrity Documents, Claims Massive Chinese Voter Data Breach (VIDEO) - SRN News Google News Security
- Trump declassifies intelligence on massive Chinese voter data breach, election vulnerabilities; urges passage of SAVE America Act - Florida’s Voice Google News Security
- CISA urges immediate action on actively exploited Fortinet flaws BleepingComputer
- Trump accuses China of massive US election data breach - Nikkei Asia Google News Security
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code The Hacker News
- Hacker puts data of more than 51 million Badoo users up for sale - Escudo Digital Google News Security